Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.8% | — | Totolink N200reAI | 29/4/2026 | 17/6/2026 | TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function. | |
| Analizada | Crítica (9.1) | 0.34% | — | Totolink A3300r FirmwareTotolink N200re Firmware | 15/12/2025 | 17/6/2026 | TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote). | |
| Analizada | Media (6.5) | 1.1% | — | Totolink N200re Firmware | 15/12/2025 | 17/6/2026 | TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName. | |
| Analizada | Baja (2.1) | 2.4% | — | Totolink N200re Firmware | 8/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Hostname leads to os command injection. The attack may be launched… | |
| Modificada | Alta (7.2) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Totolink N200RE 9.3.5u.6139_B20201216. This affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument lang leads to stack-based buffer overflow. The attack may be launched remotely. The… | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this vulnerability is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ePort leads to stack-based buffer overflow. The attack can be launched remotely. The exploit… | |
| Modificada | Crítica (9.8) | 1.4% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 1.5% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument eTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit… | |
| Modificada | Alta (8.8) | 1.4% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. Affected by this issue is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument pppoeUser leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (4.3) | 0.66% | — | Totolink N200re-v5 Firmware | 26/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the attack remotely. The complexity of an attack is rather high. The… | |
| Modificada | Crítica (9.1) | 1.1% | — | Totolink N200re V5 Firmware | 10/1/2024 | 17/6/2026 | Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi password, without logging into the management page. | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink N200re Firmware | 8/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink N200re Firmware | 8/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. Affected is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink N200re Firmware | 8/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink N200re Firmware | 8/1/2024 | 17/6/2026 | A vulnerability has been found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This vulnerability affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument host_time leads to os command injection. The attack can be initiated remotely. The exploit has… | |
| Modificada | Alta (8.8) | 3.7% | — | Totolink N200re-v5 Firmware | 4/9/2023 | 17/6/2026 | A vulnerability classified as critical has been found in TOTOLINK N200RE V5 9.3.5u.6437_B20230519. This affects the function Validity_check. The manipulation leads to format string. It is possible to initiate the attack remotely. The root-cause of the vulnerability is a format string issue. But the impact is to bypass… | |
| Modificada | Media (5.5) | 0.28% | — | Totolink N200re Firmware | 18/5/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is possible to launch the attack on the local… | |
| Modificada | Crítica (9.8) | 0.94% | — | Totolink N200re-v5 Firmware | 2/2/2023 | 17/6/2026 | A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials. | |
| Modificada | Media (6.1) | 0.57% | — | Totolink N200re FirmwareTotolink N100re Firmware | 2/5/2022 | 17/6/2026 | A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element. | |
| Modificada | Alta (8.8) | 4.2% | — | Totolink A3002r FirmwareTotolink A3002ru-v1 FirmwareTotolink A3002ru-v2 FirmwareTotolink A702r-v2 Firmware+9 | 9/12/2020 | 17/6/2026 | TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router. | |
| Modificada | Alta (8.8) | 25% | 💥 Exploit | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N301rt FirmwareTotolink N302r Firmware+4 | 27/1/2020 | 17/6/2026 | On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through… | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+14 | 27/1/2020 | 17/6/2026 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through… |